KB5089549 and the New Secure Boot PowerShell Scripts in Windows 11: What IT Pros Need to Know

Microsoft’s May 2026 cumulative update for Windows 11, KB5089549, introduced more than the usual monthly security fixes. Buried inside the release was something many IT professionals immediately noticed after patching their systems: a brand-new C:\Windows\SecureBoot folder containing several PowerShell scripts focused on Secure Boot certificate management.

For enterprise admins, endpoint engineers, and security teams, this update signals an important shift in how Microsoft is preparing organizations for the upcoming Secure Boot certificate expiration events beginning in June 2026.

This is not just another Patch Tuesday update. It is part of a much larger security initiative around UEFI trust, Secure Boot resiliency, and future-proofing Windows devices against boot-level security issues.

In this post, I’ll break down:

  • What KB5089549 introduced
  • Why Microsoft added the new SecureBoot folder
  • Where the PowerShell scripts are located
  • What each script does
  • How organizations can use them safely
  • Why this matters for modern endpoint management

What is KB5089549?

KB5089549 is the May 2026 cumulative security update for:

  • Windows 11 version 24H2
  • Windows 11 version 25H2

The update advances systems to:

  • Build 26100.8457
  • Build 26200.8457

Alongside normal Patch Tuesday security fixes, Microsoft also added infrastructure changes related to Secure Boot certificate deployment and validation.

One of the most important additions was this statement from Microsoft:

“This update adds a new SecureBoot folder under C:on eligible devices.”

Why Microsoft Added The Secure Boot Folder

The short answer is this:

Secure Boot certificates are expiring.

Many Windows devices currently rely on Secure Boot certificates that begin expiring in June 2026. If organizations fail to update these certificates correctly, some devices could eventually encounter secure boot validation problems or boot trust issues.

Microsoft is trying to avoid a repeat of past firmware and boot chain complications by introducing a controlled rollout process.

Instead of blindly deploying certificate updates to every device immediately, Microsoft is:

  • Gathering device readiness telemetry
  • Validating update success signals
  • Providing staged rollout guidance
  • Giving enterprises automation tools to manage deployments safely

That is where the PowerShell scripts come into play.


Where The Secure Boot Scripts Are Located

After installing KB5089549 on supported systems, you may notice a new directory:

C:\Windows\SecureBoot

Inside the folder are several PowerShell scripts and supporting files intended for IT administrators and enterprise deployment teams.

The folder is not malware, ransomware, or a hidden attack mechanism. It is a Microsoft-provided toolkit for Secure Boot certificate lifecycle management.


What Are These Scripts Designed To Do?

The scripts are primarily intended to help organizations:

  • Detect Secure Boot update readiness
  • Verify certificate deployment status
  • Validate EFI and boot environment conditions
  • Assist with staged deployment workflows
  • Automate rollout procedures in managed environments
  • Reduce risk during Secure Boot servicing

Microsoft specifically noted that the scripts are meant for:

“Organizations with IT professionals who actively manage updates across their device fleet.”

This is important.

These are not consumer-focused scripts. They are enterprise operational tools.


Understanding The Bigger Secure Boot Picture

To understand why this matters, you need to understand how Secure Boot works.

Secure Boot is part of the UEFI firmware security chain. Its purpose is to ensure only trusted bootloaders and signed operating system components are allowed to start during the boot process.

If malicious code modifies the boot sequence, Secure Boot helps block it before Windows even loads.

This is especially important because boot-level malware and UEFI attacks continue to evolve. Researchers have repeatedly demonstrated how firmware-level compromises can bypass traditional operating system protections.

The challenge is that Secure Boot itself relies on trusted certificates and signing infrastructure.

When certificates expire, systems must be updated carefully without breaking trust relationships between firmware, bootloaders, and operating system components.

That is exactly what Microsoft is preparing for here.


Common Scripts You Will Find

The exact contents may evolve over time, but administrators have reported scripts focused on areas such as:

  • Certificate status validation
  • Secure Boot eligibility checks
  • Rollout orchestration
  • Logging and compliance verification
  • Detection reporting

Some scripts are designed to run locally, while others are intended to integrate into enterprise deployment workflows through:

  • Microsoft Intune
  • Configuration Manager
  • Group Policy
  • PowerShell remoting
  • Deployment orchestration platforms

Example: Checking Secure Boot Status

One of the most common tasks is verifying whether Secure Boot is enabled on a device.

A simple PowerShell example:

Confirm-SecureBootUEFI

If Secure Boot is enabled, the result returns:

True

If the system does not support Secure Boot or it is disabled, you may receive errors or a False result.


Why Is Microsoft Taking A “Safe Rollout” Approach?

Microsoft specifically mentioned a “controlled and phased rollout” for these certificate updates.

That wording matters.

Secure Boot changes can potentially affect:

  • Device bootability
  • Firmware trust chains
  • Third-party bootloaders
  • Recovery environments
  • Legacy hardware
  • Custom imaging workflows

A failed Secure Boot deployment at scale could become a major operational incident for enterprises.

That is why Microsoft appears to be emphasizing:

  • Telemetry validation
  • Gradual deployment
  • Readiness assessment
  • High confidence targeting

The included scripts help administrators verify conditions before broad rollout.


How Enterprises Should Approach These Scripts

Do not immediately deploy these scripts blindly across production environments.

Instead:

1. Test In A Lab Environment

Start with:

  • Test devices
  • Pilot rings
  • Non-production systems

Validate:

  • Firmware compatibility
  • BIOS versions
  • BitLocker interactions
  • Secure Boot state
  • Recovery workflows

2. Inventory Your Environment

Understand:

  • Which systems support Secure Boot
  • Which devices have outdated firmware
  • Which systems have custom boot configurations

This becomes especially important for older hardware and long-lived enterprise images.


3. Review The Scripts Before Deployment

Even though these are Microsoft-provided scripts, always review:

  • Variables
  • Registry changes
  • EFI modifications
  • Logging behavior
  • Exit codes
  • Rollback handling

Security and endpoint teams should understand exactly what automation is being introduced into the environment.


4. Integrate Into Active Deployment Rings

Organizations already using phased deployment models should integrate Secure Boot servicing into:

  • Test rings
  • Early adopters
  • IT pilot groups
  • Production waves

This aligns well with Microsoft’s own servicing philosophy.


Known Issues With KB5089549

Like many cumulative updates, KB5089549 has not been entirely problem-free.

Microsoft acknowledged installation failures associated with error:

0x800f0922

In many cases, the issue appears tied to insufficient EFI System Partition (ESP) free space.

Some admins also reported:

  • Rollbacks during reboot
  • Driver compatibility issues
  • EFI partition servicing failures
  • Container servicing errors
  • Boot-related deployment complications

This further reinforces why Secure Boot servicing requires careful rollout planning.


Why This Matters For Modern Endpoint Management

This update highlights a larger trend in Windows management.

Endpoint security is increasingly moving deeper into the platform stack:

  • TPM
  • Secure Boot
  • UEFI
  • Virtualization-based security
  • Hardware-backed identity
  • Firmware trust

Modern Windows security is no longer just about antivirus or operating system patching.

Organizations now need operational visibility into firmware trust and platform integrity.

That is why Microsoft is investing more heavily in automation, telemetry, and managed rollout mechanisms around Secure Boot infrastructure.


Final Thoughts

KB5089549 may initially look like a normal cumulative update, but the addition of the SecureBoot folder and PowerShell tooling makes it one of the more interesting Windows 11 servicing updates in recent memory.

Microsoft is clearly preparing organizations for the next phase of Secure Boot certificate management, and these scripts are part of that preparation.

For IT professionals, this is a reminder that modern Windows servicing increasingly extends beyond the operating system itself and into firmware trust, boot security, and hardware-backed protection models.

If you manage Windows devices at scale, now is the time to:

  • Review your Secure Boot posture
  • Validate firmware readiness
  • Test certificate deployment workflows
  • Understand how these new scripts operate

The organizations that prepare early will likely avoid a lot of future troubleshooting pain later.


Sources

Microsoft KB5089549 Update Information
https://support.microsoft.com/en-us/topic/may-12-2026-kb5089549-os-builds-26200-8457-and-26100-8457-28ec2a99-4bbe-481d-a340-5c6cf18d9acb

Updated Boot Status Report With Windows Autopatch
https://techcommunity.microsoft.com/blog/windows-itpro-blog/updated-secure-boot-status-report-in-windows-autopatch/4517920

Deployment Research
https://www.deploymentresearch.com/secure-boot-rollout-scripts-added-in-may-2026-security-update

4sysops
https://4sysops.com/archives/windows-11-secureboot-folder-powershell-scripts-explained/

PCWorld
https://www.pcworld.com/article/3144594/windows-11-new-secureboot-folder-isnt-malware-heres-what-it-does.html

Windows Central
https://www.windowscentral.com/microsoft/windows-11/microsoft-confirms-may-2026-update-install-failure-with-error-0x800f0922-on-windows-11-and-provides-mitigation

Research on UEFI and Boot Security
https://arxiv.org/abs/2601.07402

Reddit Community Discussion
https://www.reddit.com/r/WindowsUpdate/comments/1tbsm0v/202605_security_update_kb5089549_262008457/

Microsoft Technical Takeoff 2022

Join Microsoft for four days of demos, deep dives, and live Ask Microsoft Anything (AMA) sessions from October 24-27, 2022, led by Microsoft engineering and designed to get you up to speed on the latest features, capabilities, and scenarios for Windows11 and Microsoft Intune, including Windows 365 and much more. There will be experts from the engineering and product teams ready to answer your questions during each session.

How do you participate?
Go to https://aka.ms/TechnicalTakeoff and select the sessions you want to attend, and then click on RSVP to save your spot, receive event reminders, and have the ability to post your questions in advance and also during the event. (Note: You must be signed in to the Tech Community to RSVP and participate in the live Q&A, but sessions can be viewed without signing in). See the video below for a quick tutorial on how to sign up.

The tweet below has been liked, shared, and retweeted by IT pros with lots of excitement for this awesome event. Follow me on Twitter and help amplify this message. Thanks.

See below for a listing of the deep dive sessions, demos, AMAs, and the Office Hours.

All times below listed for Pacific Daylight Time (PDT)

Monday, October 24

7:00 AMLet’s talk Windows and Intune
7:30 AMDefault hardening in Windows 11, version 22H2
8:00 AMZero in on Zero Trust with unified endpoint security management from Microsoft
8:30 AMWindows 365 security best practices
9:00 AMAMA: Cloud attach vs. cloud only: the debate
10:00 AMWhen is my device going to update?
10:30 AMIntroducing advanced endpoint management solutions for Microsoft Intune
11:00 AMWhat’s new and how to deploy Windows 365 Business
11:30 AMProviding access to on-premises resources for mobile devices using Microsoft Tunnel

Tuesday, October 25

7:00 AMWindows Autopilot: notes from the field
7:30 AMPolicy management with Microsoft Intune
8:00 AMManage and secure Cloud PCs and your workforce with Microsoft Intune
8:30 AMYour guide to going cloud-native
9:00 AMWindows Update for Business deployment service + Intune: the latest and greatest
9:30 AMWindows 365: Enhance the end user experience with cloud-optimized PC management
10:00 AMMeet the new Windows Update for Business reporting experience
10:30 AMSecuring corporate credentials with Enhanced Phishing Protection
11:00 AMThe Store of the future
11:30 AMWindows 365 end-user experiences: what’s new and what’s next

Wednesday, October 26

7:00 AMJump into modern managed devices with Azure AD Join
7:30 AMGrouping, targeting, and filters: recommendations in Microsoft Intune
8:00 AMManaging local admin account passwords in AD and Azure AD
8:30 AMBalancing security and flexibility when implementing Windows Defender Application Control (WDAC)
9:00 AMUnderstanding Azure Virtual Desktop and Windows 365 for hybrid work
9:30 AMBuilding a tamper resilient endpoint with Microsoft Intune and Microsoft Defender
10:00 AMFeedback wanted! Making the admin experience great in Microsoft Intune
11:00 AMCitrix HDX Plus for Windows 365 deep dive
11:30 AMAdvanced management of Universal Print

Thursday, October 27

7:00 AMConfiguration as Code in Microsoft Intune
7:30 AMWhat is a policy? And why shouldn’t I set registry keys?
8:00 AMWindows 365 Government: setup and configuration
8:30 AMAMA: Windows Autopatch
9:30 AMWindows 365 provisioning and Azure Network Connection (ANC) internals
10:00 AMAMA: Delivery Optimization & Connected Cache
10:30 AMIncrease productivity for shift and part-time workers with Windows 365
11:00 AMAMA: Device Health Attestation – security benefits and integrations
11:30 AMHow to build app confidence with Test Base

As of Sunday, October 23, 2022, we have added a Microsoft Edge AMA on Wednesday, October 26th at 12PM PT. Check it out: https://aka.ms/TTAMA/MicrosoftEdge.

I’m excited for this event which a handful of us at Microsoft helped organize, planned and produced this amazing technical event for IT pros. Looking forward to seeing you at Microsoft Technical event, for you learning, and engagements.

Harjit Joins Microsoft!

The time has come to let the ?‍? out of the bag and make the formal announcement. On May 21, 2021, I wrote a blog post where I mentioned that I left my 18 year career in Higher-Ed as a Senior Systems Administrator at the University of Vermont.

I am excited to announce that as of today, June 7, 2021, I have joined Microsoft as a Customer Engineer for Microsoft 365. My role covers a variety of solutions under the Microsoft 365 umbrella including Modern Management which I’m very passionate and super excited about. I can finally say that I’m now a “Blue Badge” and my dream of joining Microsoft has come true!

There is so much that I want to mention and perhaps, I’ll start with my family. My wife Jenny and my daughters Sabrina and Hannah have been my rock, strength, motivation, strong supporters for what I do, and they highly encouraged me to pursue my dreams and passion. Thank you!

I’ve been privileged and honored to be a Microsoft MVP since January 2017, and I have grown and learned so much since then, as well as had many amazing opportunities, from guest blogging, consulting work, product reviews, NDA opportunities with Microsoft, Subject Matter Expert (SME) on various webinars and technical user groups, speaking engagements with several conferences including Microsoft Ignite in Orlando, Microsoft Ignite The Tours in Milan, Johannesburg, and Dubai (unfortunately COVID-19 cancelled my speaking gigs in Zurich, Mumbai, Bangalore, Tel-Aviv, and Chicago), TechMentor, IT/Dev Connections, and the one close to my heart and my favorite MMS aka MMSMOA, to name a few. During this journey, I developed strong bonds, positive reputation, respect, and trust among Microsoft product groups, MVP Program leadership, fellow Microsoft MVPs, vendors, event organizers, IT Professional community, mentees, my wonderful followers, and close friends. Thank you to all of you for your support, guidance, encouragement, and friendships.

Today also marks the end of the road for my Microsoft MVP award, which is something one has to give up upon joining Microsoft as an employee. I will continue to be a valuable resource not only to the MVP Program, the leadership, but to the IT Pro community as well, and will continue to empower everyone and help improve what I can. Thank you Betsy Weber, Rochelle Sonnenberg, and Christian Talavera for allowing me to do what I do, and most importantly for all the amazing opportunities as well as for my inclusivity as one of the trusted leaders within the MVP program. Also, Thank you Cathy Moya for the same and so much more. It’s amazing that we are all colleagues now. ??‍???

There are a few people who I would like to mention and recognize, who have been instrumental for my next career phase with Microsoft. The offline chats, references, internal recommendations, referring to open positions, keeping me in check, pushing me harder, motivations, encouraging me to stay positive, mentorship, discreet conversations, trust, friendships, and so much more, meant a lot to me and I’m forever appreciative and grateful. I know I am going to miss mentioning someone or another, and for that I apologize in advance and please forgive me. In no particular order, Thank you very much Noel Fairclough, Rod Trent, John Deardurff, Art Hogarth, Cathy Moya, Heather Poulsen, Kerim Hanif, Kris Loranger, Joe Lurie, and last but not least Julie Andreacola.

Thank you to Prayer Solanky who I consider my brother, and has been there for me in good times, during challenging moments of my life, provides tons of valuable advice, keeps me grounded and humble always, and who I trusted with my journey to Microsoft.
Also, Thank you to my wonderful friends Mick Pletcher, Anoop Nair, Richard Hay, John Yoakum, Jen Sheerin, Ben Dumke, Mary Jo Foley, Scott Ladewig, Ben Whitmore, James Petty, Jitesh Kumar, Octavio Rodriguez, Damien Van Robaeys, Nick Pilon, Benoit Lecours, Brian Mason, Greg Ramsey, Mirko Colemberg, Johan Arwidmark, Anne Baker, Peter De Tender, Adnan Hendricks, Team MMS, The Krewe, Team Devops Collective, Team SCDudes, and so many more. Last but not least, my close “Ignitable” friends (Pat, Dean, Brandon, Kenji, Stu, Henrik, Stuart, Joe, Travis, and Jin.

As I celebrate this happy occasion, I’m also reminded of my brother Amarjit who passed away on this very day (June 7th) in 2015. I miss him very much, but I know he is proud of me and is watching over me from heaven. ???

With all that said, it’s time to kick start my new adventures with the company and people I love, embrace the unique opportunities, advocate and evangelize modern technologies, support the IT Pro community, and I’m ready to “empower every person and every organization to achieve more”! ?‍??‍??‍??‍???✔

Microsoft MVP 2019-2020 Renewal

I’m so Thankful, honored, and excited to receive the above email from the Microsoft Most Valuable Professional (MVP) Award team confirming my award renewal for the 2018-2019 year. This is my second consecutive award since receiving my first one on January 1, 2017. It has been a wonderful, exciting, fun, challenging, and rewarding experience with endless opportunities.

The MVP award has provided me with some great opportunities in terms of my career growth, skill development, and avenues to give back and help others in the IT Professional community. I have been invited to speak at conferences such as Microsoft Ignite (Orlando 2017 & 2018), MVP Community Connections (Boston and New York City), TechMentor, IT/Dev Connections, MMSMOA, user groups, various webinars, as well as opportunities to guest blog, join technical expert panelist, review technical books, test and evaluate software, provide technical expertise, guest speak on podcasts, community reporter at Microsoft Ignite 2017, community engagement specialist at various events, and much more.

This is my 3rd MVP Award and I am very grateful and appreciative for it and for the various opportunities provided to me over time. Thank you very much to each and every one of you for making me successful in my efforts as a MVP, IT Professional, and community contributor, and for providing me with the valuable resources and networking opportunities. Thank you!

MVP Profile

Windows 10 October 2018 Update (v1809) Available in VLSC

The ISO download for Windows 10 October 2018 Update edition (version 1809) has been released and is now available from the Microsoft Volume Licensing Service Center (VLSC) portal. You’ll find the 64-bit ISO file with a download size of 4505 MB. The 32-bit version is also available for download (3278MB).

Here is a good article on “How to verify if you have downloaded or installed the latest version of Windows 10”. I would recommend that you check out Michael Niehaus’ blog post where he shares some important information regarding the changes with the volume license media and upgrade packages with Windows 10, starting with v1709. There is only one ISO with a single WIM (Windows Image) file that contains all the volume license images as listed below:

Here’s what’s new in Windows 10 October 2018 Update and Office. And here’s some additional information on how to get Windows 10 October 2018 Update.

You can check out the known issues HERE!

Microsoft MVP 2018-2019 Renewal

I’m so Thankful, honored, and excited to receive the above email from the Microsoft Most Valuable Professional (MVP) Award team confirming my award renewal for the 2018-2019 year. This is my second consecutive award since receiving my first one on January 1, 2017. It has been a wonderful, exciting, fun, challenging, and rewarding experience with endless opportunities.

The MVP award has provided some great opportunities for me in terms of my career growth, skill development, and avenues to give back and help others in the IT Professional community. I have been invited to speak at conferences such as Microsoft Ignite (Orlando 2017), MVP Community Connections (Boston and New York City), TechMentor, IT/Dev Connections, MMSMOA, user groups, webinars, as well as opportunities to guest blog, expert panelist, review technical books, test and evaluate software, provide technical expertise, guest podcaster, community reporter at Ignite 2017, community engagement specialist at various events, and much more.

I am very grateful and appreciative for my MVP award and various opportunities provided to me over time. Thank you very much to each and every one of you for making me successful in my efforts as a MVP, IT Professional, and community contributor, and for providing me with the valuable resources and networking opportunities. Thank you!

ADMX Template For Windows 10 April 2018 Update (1803) Now Available

On April 30, 2018, Microsoft released the Windows 10 April 2018 Update (1803) build to customers worldwide. The following tools to support this latest release has been made available, which includes Windows 10 Administrative Templates (.ADMX), Windows Assessment and Deployment Kit (ADK), and the Remote Server Administration Tools (RSAT) for Windows 10 April 2018 Update.

Windows 10 Administrative Template (.ADMX)

Remote Server Administration Tools for Windows 10 (RSAT)

Windows 10 Assessment and Deployment Kit (ADK)

Microsoft Office 2016 Administrative Templates and Office Customization Tool is also available for download.

Follow @Hoorge on Twitter and join Tech Konnect on Facebook and Twitter to stay current on technology related matters.

Remote Server Administration Tools (RSAT) For Windows 10 v1803

The latest version of the Remote Server Administration Tools (RSAT) for Windows 10 April 2018 Update v1803 have been released. The download is available here. You will find the following download files available for version 1.0 corresponding to x86 or x64 Operating Systems:

  • WindowsTH-RSAT_WS_1803-x64.msu (95.1MB)
  • WindowsTH-RSAT_WS_1803-x86.msu (69.9MB)
  • WindowsTH-RSAT_WS2016-x64.msu (92.3MB)
  • WindowsTH-RSAT_WS2016-x86.msu (69.5MB)

See here if you would like to determine if a computer is running 32-bit or 64-bit Windows OS.

Additional Information:

When to use WS_1803 RSAT Package: When managing Windows Server, version 1803 or Windows Server, version 1709
When to use WS2016 RSAT Package: When managing Windows Server 2016 or previous versions

Known Issues that may impact RSAT functionality:

Issue: DNS Tools missing
Impact: WS_1709 RSAT package users
Resolution: Use the WS_1803 or WS2016 RSAT package or apply this workaround

Issue: Cannot turn off individual RSAT components
Impact: WS_1803 and WS_1709 RSAT package users on Windows 10 1803/1709 (April 2018 Update/Fall Creators Update)
Resolution: Use the WS2016 RSAT package on Windows 10 1607 (Anniversary Update)

Issue: Tabs missing from MMC Properties
Impact: Windows 10 clients before 1607 (Anniversary Update)
Resolution: Update to the latest version of Windows 10 client and reinstall RSAT

Issue: Shielding Data File Wizard cannot create shielding data files
Impact: WS_1709 RSAT package users on Windows 10 1709 (Fall Creators Update)
Resolution: Use the WS_1803 RSAT package on Windows 10 1803 (April 2018 Update), or use the WS2016 RSAT package on Windows 10 1607 (Anniversary Update) to create shielding data files for Windows shielded VMs, or the built-in RSAT tools in Windows Server, version 1709 to create shielding data files for both Windows and Linux shielded VMs.

Issue: Template disks created from the Template Disk Wizard do not boot
Impact: WS_1709 RSAT package users on Windows 10 1709 (Fall Creators Update)
Resolution: Use the WS_1803 RSAT package on Windows 10 1803 (April 2018 Update), or use the WS2016 RSAT package on Windows 10 1607 (Anniversary Update) to create template disks for Windows shielded VMs, or the built-in RSAT tools in Windows Server, version 1709 to create shielding data files for both Windows and Linux shielded VMs.

Follow me (@Hoorge) on Twitter and join Tech Konnect on Facebook and Twitter (@TechKonnect) to stay current on technology related matters.

How To Obtain Computer Serial Number With PowerShell

To obtain the local computer serial number, use this one-liner PowerShell command:

get-wmiobject -Class win32_bios | select PSComputerName,SerialNumber

To obtain the serial number of a remote computer, use this one-liner PowerShell command (PSRemoting must be enabled:

get-wmiobject -ComputerName <name of computer> -Class win32_bios | select PSComputerName,SerialNumber

Configure PowerShell Remoting

To perform actions on remote computers using PowerShell, you’ll need to setup PowerShell Remoting. Here are the steps:

1. In a PowerShell CMD window that is running under the administrator context, run the following command:

Enable-PSRemoting –force

2. Configure WinRM to run automatically:

Set-Service WinRM -StartMode Automatic

3. Verify the start mode was set correctly and that it is currently running:

Get-WmiObject -Class win32_service | Where-Object {$_.name -like “WinRM”}

4. Configure so that all remote hosts are trusted:

Set-Item WSMan:localhost\client\trustedhosts -value *

5. Verify that the remote trusted hosts has taken effect:

Get-Item WSMan:\localhost\Client\TrustedHosts

Written by myITforum